HNHacker News
TopNewBestAskShowJobs

bink

2,474 karma · joined August 27, 2016

submissionscomments
bink··on US missile hit military base near Iran school, video analysis shows
I've only seen it on TV. You can see it about 20 seconds into this video:

https://www.cnn.com/world/video/video-appears-to-show-us-str...

bink··on US missile hit military base near Iran school, video analysis shows
The story is because these are precision strikes and the US is feigning ignorace. Satellite photos show that each building on that block was hit dead-center and destroyed, yet the US is refusing to admit responsibility. Sure, mistakes are made during war, but this one was particularly egregious. That building hadn't been used as a military barracks in over a decade. Israel immediately said they were not operating in that area. Iran said none of their missiles were in the area. The US has said for a week now that it was "investigating" despite knowing it targeted that facility. That's yet another lie. They know they accidentally killed over a hundred little girls and as usual would rather lie than admit a mistake.
bink··on The Pentagon threatens Anthropic
Imagine a world where in order to do business in the US you must grant the government control of your company. This sounds worse than even the most alarmist China takes.
bink··on Binance fired employees who found $1.7B in crypto was sent to Iran
donations to an inauguration fund.
bink··on UNIX99, a UNIX-like OS for the TI-99/4A (2025)
Thanks. I wasn't looking forward to browsing all those pages in the hopes of finding the source. Did they never put it up on GitHub?
bink··on Making frontier cybersecurity capabilities available to defenders
I hope this is better than their competitors products. So far I've been underwhelmed. They basically just find stuff that's already identified by static analysis tooling and toss in a bunch of false positives from the AI scans.
bink··on Homeland Security Wants Social Media Sites to Expose Anti-ICE Accounts
Even if you could delete comments, in this day and age it's not a real deletion. They'd just put a "deleted" flag on the comment in the DB.
bink··on Waymo exec reveals company uses remote workers in the Philippines
What I found interesting about this is that on several occasions I've seen Waymos get confused and block intersections (and once Muni tracks). Each time they've sat there for at least 10-15 mins until a police officer showed up and tapped on the window. Then it was another 10-15 mins before the vehicle started to move again. What are these agents doing?
bink··on Discord will require a face scan or ID for full access next month
Wire fraud is more than just lying to someone over the Internet. It requires a financial gain.
bink··on Opus 4.6 uncovers 500 zero-day flaws in open-source code
Yes. As a security researcher this always annoys me.
bink··on Netbird – Open Source Zero Trust Networking
It doesn't automatically update, that's true. But I think the typical way to deal with this is to have a nebula subdomain. www.nebula.example.com instead of www.example.com.
bink··on Amiga Unix (Amix)
Sun and NeXT also sold 68k Unix workstations at the time. IMHO, The thing about Amiga was that it was not seen as a business machine. Commodore in general was seen as a home computer, and really one aimed at gaming first. AFAIK they didn't even have computers with the specs to compete with what Sun, SGI, HP, and others were doing.
bink··on Netbird – Open Source Zero Trust Networking
Nebula uses lighthouses instead of DNS for finding other nodes.

https://github.com/slackhq/nebula?tab=readme-ov-file#2-optio...

bink··on Guest Post from an Iranian
There definitely won't be boots on the ground and that's kinda the point. Even if we had boots on the ground there's no guarantee that the US getting involved will make things better for the people of the region. We couldn't deliver democracy for Afghanistan after two decades but there are still people who think we'll be greeted as liberators in Iran and we'll be able to claim "mission accomplished" after a few months.
bink··on Guest Post from an Iranian
There's no doubt what's happening in Iran is a massacre by a dictatorial regime, but good grief the parallels between the rhetoric now and that of 2003 are impossible to ignore. I thought we had moved past the idea that the US could just bomb a country into a better future.
bink··on County pays $600k to pentesters it arrested for assessing courthouse security
The purpose of the paper isn't to act as a "get out of jail free" card. It's to (hopefully) prevent the handcuffs from coming out while they verify the information. They're expected to contact the appropriate people before letting anyone go. Usually the emergency contact would be nearby and come to the site to discuss the project with their security team.
bink··on County pays $600k to pentesters it arrested for assessing courthouse security
I wasn't trying to suggest they did or didn't have the right documentation. I honestly don't know. I was just explaining how we normally operated. The idea that the emergency contact wouldn't answer, or even worse deny we had authority seems impossible to me... At least if you're doing things the way we did.
bink··on County pays $600k to pentesters it arrested for assessing courthouse security
I completely agree. Hiding from the cops puts everyone in danger. But to be clear I wouldn't be hiding from the security guards either once they had found evidence of our test. It was really only if they were nearby and unaware anything was happening that we found it OK to hide from them.

The whole point is to test security. Ideally you want to be found because that means that they have reasonable security in place and you can attest to that.

bink··on County pays $600k to pentesters it arrested for assessing courthouse security
I performed these types of physical pen tests years ago. If we were testing security for something like a courthouse we would've had a card on each of us with the personal cell phone number of the county clerk along with a statement of work that described exactly what we were authorized to do, with signatures. In some cases we'd have a backup contact number for more dangerous stuff. The idea that the emergency contact would not answer the phone would've seemed ludicrous. They were always aware of where we were and what we were doing at all times.

Damaging property was never approved. Drinking alcohol before a test would never happen. The insurance risk alone would've been nuts, not to mention the reputational damage if someone smelled it on your breath. Hiding from law enforcement? I'd need to know more about that. If a cop shows up with a gun you absolutely do not hide. If it's a security guard on rounds and you're waiting for them to move on... sure.

It was often dangerous though. Some security and law enforcement types take it personally that they're being "tested" and do not react well. We always tried to have some former law enforcement or military with us because they were less likely to be targeted for abuse than us hackers/nerds.

bink··on Prediction markets are ushering in a world in which news becomes about gambling
It's amazing how many people on HN didn't bother to actually read the article.
bink··on Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
As a security dude I spend way too much of my time fixing missing anchors or unescaped wildcards in regex. The good news is that it's trivial to detect with static analysis tooling. The bad news is that broken regex is often used for security checks.
bink··on Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
I think it comes down to what you do with the access. Since this is a public repo I don't think I'd be too upset at the addition of a new admin so long as they didn't do anything with that access. It's a good way to prove the impact. If it were a private repo I might feel differently.
bink··on FBI raids Washington Post reporter's home
There are several groups out there that train journalists (and others) about digital security.

https://freedom.press/digisec/

https://tcij.org/initiative/journalist-security-training/

https://ssd.eff.org/playlist/journalist-move

bink··on The chess bot on Delta Air Lines will destroy you (2024) [video]
Underfunded and constantly side-tracked by cargo bots.
bink··on The chess bot on Delta Air Lines will destroy you (2024) [video]
I swear this happens to me almost every time I fly.
bink··on Anthropic: Developing a Claude Code competitor using Claude Code is banned
Their contracts prohibit it for certain classes of users, but if you're really worried about it Anthropic also offers a "bring your own cloud" version where the data supposedly never leaves your infrastructure.
bink··on Bluetooth Headphone Jacking: A Key to Your Phone [video]
The government also doesn't let people conduct sensitive or classified conversations over un-certified protocols or devices. Unless the NSA was participating in the bluetooth encryption standards decisions they aren't going to allow those devices to be used by the President or VP. IMHO though, it's probably more that there were security trade-offs made when developing the standards and the government isn't OK with those types of trade-offs. It doesn't mean they're horrible, just that they aren't verified to be secure enough for sensitive governmental purposes.
bink··on PG&E outages in S.F. leave 130k without electricity
Are you suggesting Ukraine and Russia don't also have occasional outages caused by equipment failures or bad decisions unrelated to the war?
bink··on Waymo halts service during S.F. blackout after causing traffic jams
This only works if they have cell service and enough human drivers to handle all of their cars.
bink··on Waymo halts service during S.F. blackout after causing traffic jams
It was predicted by many, including me. It'll be a lot worse in an earthquake where power and cell service are out and there's debris and road damage. Good luck to our first responders.

https://news.ycombinator.com/item?id=41688847

← PreviousPage 2 of 22Next →